product update

Google's Gemini Spark Gains Chrome Web-Browsing to Automate Flight Bookings and Errands

TL;DR

Google's agentic AI assistant Spark now integrates with Chrome, letting it use logged-in accounts and saved passwords to handle tasks like researching flights and scheduling apartment viewings. The feature is rolling out in the US now, alongside expanded Spark access for Google AI Pro subscribers in over 160 countries.

2 min read
0

Google has added Chrome web-browsing integration to Spark, its agentic AI assistant, allowing the tool to use a user's logged-in accounts and saved passwords to complete tasks directly in the browser.

According to Google, once a user logs in to Chrome, Spark "can use your logged-in accounts and saved passwords to handle tedious web errands." The company's two provided examples: researching flight options and starting the booking process, and scheduling viewings of apartments. Google has not disclosed a broader list of supported tasks.

Rollout and access

The Chrome integration is rolling out now in the US, with Google saying additional regions will follow. The announcement coincides with an expansion of Spark access to Google AI Pro subscribers in more than 160 countries. Spark also integrates with Google Workspace apps, extending its reach beyond the browser into email, documents, and scheduling tools.

Safety claims

Handing an AI assistant access to passwords and logged-in sessions raises an obvious risk: prompt injection, where malicious instructions hidden on a webpage or in user-generated content hijack the assistant into taking unwanted actions, such as initiating financial transactions or exfiltrating sensitive data.

Google says it is "investing in a layered defense that includes both deterministic and probabilistic defenses to make it difficult and costly for attackers to cause harm." The company has not detailed what these deterministic and probabilistic defenses actually consist of, nor published any benchmark or red-team results demonstrating their effectiveness against prompt injection attacks.

As a guardrail, Google says Spark will not complete payments autonomously. Purchases are routed back to the user for final review and confirmation, meaning the assistant can advance a transaction to checkout but cannot execute it independently.

Engadget, which first reported the update, has asked Google for further detail on the scope of the integration and has not yet received a response.

What this means

This release fits a broader pattern among AI labs: shipping browser-connected agents before publishing rigorous, independently verifiable security guarantees. Prompt injection remains an unsolved problem industry-wide, and Google's description of its defenses—"layered," "deterministic and probabilistic"—is vague enough that it should be read as a claim, not a settled fact. The decision to keep payment completion in human hands is a sensible interim safeguard, but it also underscores that Google isn't yet confident enough in its own injection defenses to let Spark handle money unsupervised.

The narrow use cases Google highlighted—flight research and apartment viewing scheduling—suggest this is an early, limited rollout rather than a general-purpose browsing agent. Expect scope to widen alongside the wider AI Pro rollout across 160+ countries, but expect scrutiny of the safety claims to widen too, particularly from security researchers who have spent the past year demonstrating how easily browser-using agents can be manipulated by adversarial web content.

Related Articles

product update

Anthropic Relaunches Claude Code Projects to Coordinate Multiple Cloud Agents

Anthropic has relaunched Projects in Claude Code, letting users direct multiple AI agent 'threads' that work in parallel under a coordinating agent. The beta feature rolls out today to select Claude Pro and Max subscribers, with broader access planned later.

product update

Anthropic Rebuilds Claude Code Projects to Run Parallel AI Agent Threads

Anthropic has rebuilt Claude Code's Projects feature so a coordinator agent splits user goals into parallel cloud-based threads, each capable of opening pull requests and running tests. The beta is limited to select Pro and Max subscribers, with Team, Enterprise, and local execution support coming later.

product update

Instinct and Meta's Muse AI Agents Both Add Phone-Calling Features Within Hours of Each Other

Instinct and Meta's Muse AI assistants both rolled out phone-calling capabilities on September 16, 2026, letting agents book restaurants, manage service calls, and act as a concierge. Instinct is reportedly in talks to raise $1 billion at a $10 billion valuation.

product update

Google Launches Home MCP, Letting AI Agents Like Claude and Antigravity Control Smart Home Devices

Google has launched Home MCP, a Model Context Protocol server that lets AI agents like Claude, Google Antigravity, and OpenClaw interact with Nest cameras, thermostats, and Matter smart home devices. The feature is rolling out today to Google Home Premium Advanced subscribers in US English.

Comments

Loading...